Fortinet security advisory (AV26-023) - Update 1

MediumCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
Fortinet
Industries
Government
Reported by
1 outlet

On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:

  • FortiFone 7.0 – versions 7.0.0 to 7.0.1
  • FortiFone 3.0 – versions 3.0.13 to 3.0.23
  • FortiOS 7.6 – versions 7.6.0 to 7.6.3
  • FortiOS 7.4 – versions 7.4.0 to 7.4.8
  • FortiOS 7.2 – versions 7.2.0 to 7.2.11
  • FortiOS 7.0 – versions 7.0.0 to 7.0.17
  • FortiOS 6.4 – versions 6.4.0 to 6.4.16
  • FortiSASE 25.2 – version 25.2.b
  • FortiSASE 25.1.a – version 25.1.a.2
  • FortiSIEM 7.4 – version 7.4.0
  • FortiSIEM 7.3 – versions 7.3.0 to 7.3.4
  • FortiSIEM 7.2 – versions 7.2.0 to 7.2.6
  • FortiSIEM 7.1 – versions 7.1.0 to 7.1.8
  • FortiSIEM 7.0 – versions 7.0.0 to 7.0.4
  • FortiSIEM 6.7 – versions 6.7.0 to 6.7.10
  • FortiSwitchManager 7.2 – versions 7.2.0 to 7.2.6
  • FortiSwitchManager 7.0 – versions 7.0.0 to 7.0.5

Update 1

On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-25249 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-09 19:57 UTC

Related stories